Equifax: knowing about a vulnerability is not knowing it is patched
Equifax knew about the vulnerability and had told people to fix it. The gap was between instruction and verification.
A notice went out, a scan did not cover the affected system, and nobody established that the patch had actually been applied where it mattered. The lesson is not about that particular flaw. It is that a remediation process which ends at "we told them" has no idea what its own state is.
More on Real incident lessons
- Target: supplier access showed why third-party portals need strong segmentation from sensitive systemsThe partitions stop short
- Colonial Pipeline: business shutdown can follow IT compromiseNothing touched the pipe
- Help-desk identity processes are attack surfaces when social engineering can trigger password resets or MFA transferThree answers, and it moves
- British Library: recovery can outlast initial disruptionThe outage was the short part
- Hawaii false missile alert: test and live alert paths need separation because confirmation prompts cannot correct a convinced operatorA hand apart
- CrowdStrike 2024: trusted security software can be concentration riskOne roller, every machine
